Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 374

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Book: The Gone World
Circle lands $100 million from Binance to ramp up global USDC expansion
Trump slams Iran and Cuba, defends AI growth and recounts record in UN speech
Nasdaq climbs to fresh all-time high; S&P 500 is little changed as traders monitor Middle East tensions: Live updates
Trump snaps at CNN at United Nations: 'You should not be here covering me'
Trapped in minimum payments? These products can help you get out of credit card debt
phone games that get you into flow state
Book: Wide Sargasso Sea
Oil little changed after Trump tells UN that Iran will make a deal after midterm elections
Book: Murderland: Crime and Bloodlust in the Time of Serial Killers